ELSA-2015-0325

ELSA-2015-0325 - httpd security, bug fix, and enhancement update

Type:SECURITY
Severity:LOW
Release Date:2015-03-11

Description


[2.4.6-31.0.1]
- replace index.html with Oracle's index page oracle_index.html

[2.4.6-31]
- mod_proxy_fcgi: determine if FCGI_CONN_CLOSE should be enabled
instead of hardcoding it (#1168050)
- mod_proxy: support Unix Domain Sockets (#1168081)

[2.4.6-30]
- core: fix bypassing of mod_headers rules via chunked requests (CVE-2013-5704)
- mod_cache: fix NULL pointer dereference on empty Content-Type (CVE-2014-3581)

[2.4.6-29]
- rebuild against proper version of OpenSSL (#1080125)

[2.4.6-28]
- set vstring based on /etc/os-release (#1114123)

[2.4.6-27]
- fix the dependency on openssl-libs to match the fix for #1080125

[2.4.6-26]
- allow 'es to be seen under virtual hosts (#1131847)

[2.4.6-25]
- do not use hardcoded curve for ECDHE suites (#1080125)

[2.4.6-24]
- allow reverse-proxy to be set via SetHandler (#1136290)

[2.4.6-23]
- fix possible crash in SIGINT handling (#1131006)

[2.4.6-22]
- ab: fix integer overflow when printing stats with lot of requests (#1092420)

[2.4.6-21]
- add pre_htaccess so mpm-itk can be build as separate module (#1059143)

[2.4.6-20]
- mod_ssl: prefer larger keys and support up to 8192-bit keys (#1073078)


Related CVEs


CVE-2013-5704
CVE-2014-3581

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 7 (x86_64) httpd-2.4.6-31.0.1.el7.src.rpme3a05844786d912f798f285f55dc088eELBA-2020-5033
httpd-2.4.6-31.0.1.el7.x86_64.rpmac7f5207fb1cec7c820054ae4f9a6af6ELBA-2020-5033
httpd-devel-2.4.6-31.0.1.el7.x86_64.rpmc7a8ed4e765f6ca15fa56958a6ef321dELBA-2020-5033
httpd-manual-2.4.6-31.0.1.el7.noarch.rpmfec2b875d73d98caf6f1be748ca4b53bELBA-2020-5033
httpd-tools-2.4.6-31.0.1.el7.x86_64.rpmc9e514eba4a39df12607170ab2b13421ELBA-2020-5033
mod_ldap-2.4.6-31.0.1.el7.x86_64.rpm2db1783532dc8c51e10206629a3cc950ELBA-2020-5033
mod_proxy_html-2.4.6-31.0.1.el7.x86_64.rpmc005186dcc4e7e8dff6e404c03fb6d91ELBA-2020-5033
mod_session-2.4.6-31.0.1.el7.x86_64.rpmd6f18933d4d041bd3ecf2b866d8e921eELBA-2020-5033
mod_ssl-2.4.6-31.0.1.el7.x86_64.rpm632385c3720f93948a5222913824ad3bELBA-2020-5033



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete